Cryptomining attack on an AI gateway reveals a much bigger cloud security problem
Hackers broke into an Amazon cloud server acting as a doorway to AI services, planted mining software, and probed for wider access. The real worry is how much power these AI gateways hold.

Key points
- Researchers at Darktrace found attackers had broken into an AWS cloud server running LiteLLM, software that acts as a shared gateway to AI models, and installed XMRig, a program that secretly uses a victim's computing power to mine cryptocurrency.
- The compromised server carried an IAM role, an identity-and-permissions badge that grants access to cloud resources, capable of reaching Amazon Bedrock, AWS's service for running large AI models.
- A separate suspicious identity, traced to an IP address in Vietnam, attempted to enumerate and invoke Amazon Bedrock models and tried to create a new cloud user account the day after the mining malware appeared.
- The cryptomining payload is almost beside the point: AI gateways bundle credentials and model access in one place, making them a high-value target even for attackers using old, simple techniques.
- Darktrace's managed detection team caught the activity and alerted the customer in time to contain it.
The attack itself was not sophisticated. Criminals found a cloud server with its SSH port open to the public internet. SSH, or Secure Shell, is a remote-access protocol that lets administrators log in to a server from anywhere. Leaving that door open is an old mistake. Attackers hammered it with thousands of login attempts from a single external address, a technique called brute-forcing, until something gave way.
Once inside, they downloaded a ZIP file containing XMRig, which hijacks a server's processing power to earn cryptocurrency. The host then began connecting repeatedly to a mining pool, a group of computers working together to earn crypto rewards.
Why does it matter if it was just a cryptominer?
This server wasn't just any cloud machine. It was running LiteLLM, software that acts as a single shared entry point through which a company's applications talk to large AI models. Because it speaks to all those models on behalf of the company, it holds a wide set of cloud permissions. Breaking in is like stealing a hotel's master key rather than a key to one room.
Sean Malone, chief information security officer at identity-security company BeyondTrust, told CSO Online the pattern is nothing new. He's tracked the same sequence since at least 2018: open SSH port, brute-force login, XMRig miner, repeated mining-pool connections. The AI twist, stolen credentials probing AI model services, even has a name coined in 2024: LLMjacking. We first covered that technique on 9 July 2026, when a single attacker used it to tear through a major AWS environment in 72 hours.
Still, Malone agreed that AI gateways concentrate credentials, cloud permissions, and model access into a single choke point, so a routine intrusion lands on a privileged asset. Jason Soroko, senior fellow at Sectigo, put it plainly to CSO Online: these gateways are becoming brokers for identity, model access, prompts, logs, and policy. When one is exposed over SSH or backed by broad IAM permissions, it's no longer just another compute instance. It's a control point for AI operations across the whole organisation.
Darktrace flagged suspicious account activity spotted separately, a day later: a "GetSendQuota" API call from a Vietnamese IP address, attempts to enumerate and invoke AI models, and an effort to create a fresh cloud user with a randomly generated name. Creating hidden accounts is how attackers keep a foothold after initial credentials are changed. Darktrace could not link this IAM activity directly to the LiteLLM incident.
Should you worry about your personal data?
If you use AI-powered tools through your employer, this incident doesn't put your personal data at direct risk. It does show that the infrastructure behind those tools needs the same basic hygiene as any other system: close public SSH access, use private authenticated tunnels, scope IAM permissions tightly, and treat any unrecognised new cloud account as an immediate alert.



